{"id":22234,"plugin_id":"plugins_6ab01c9056c481918eac972df8fb396d","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:17:11.940Z","digest":"6caba13e6db8f7c138d073fac549f7c98249862552a19da0092894089c512345","against":null,"payload":{"description":"Perform deep Supabase Row Level Security, Data API exposure, policy, view, function, and role analysis.","included_files":[],"name":"supabase-rls-security","skill_md_contents":"---\nname: supabase-rls-security\ndescription: Perform deep Supabase Row Level Security, Data API exposure, policy, view, function, and role analysis.\n---\n\n# Supabase RLS Security\n\nUse for any Supabase database, Auth, Data API, Storage, view, function, or user-data review.\n\n## Mandatory checks\n\n- Enable RLS on every table in exposed schemas, including `public` by default.\n- Confirm Data API exposure and explicit grants separately from row policies.\n- Check every table's `SELECT`, `INSERT`, `UPDATE`, and `DELETE` model.\n- For `UPDATE`, verify both `USING` and `WITH CHECK`; also verify the required `SELECT` policy.\n- Reject `TO authenticated` without an ownership, membership, tenant, or capability predicate.\n- Prefer `TO authenticated` or `TO anon` clauses; flag deprecated `auth.role()` checks.\n- Never use user-editable `raw_user_meta_data` for authorization; use trusted server-controlled app metadata or database membership tables.\n- Review views for `security_invoker = true` on supported Postgres versions or restricted access in an unexposed schema.\n- Review `SECURITY DEFINER` functions for schema placement, explicit authorization, fixed search path, minimal grants, and default `PUBLIC` execute privileges.\n- Check storage policies, including `SELECT`, `INSERT`, and `UPDATE` for upsert behavior.\n- Review service-role usage and ensure it never reaches public clients.\n\n## Findings format\n\nReport table/schema, exposed role, operation, policy, predicate, bypass path, impact, and a safe SQL or application-level remediation. Never invent a policy without understanding the intended access model.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}